Vulnerability Details CVE-2024-34687
SAP NetWeaver Application Server for ABAP and ABAP Platform do not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
An attacker can control code that is executed within a user’s browser, which could result in modification, deletion of data, including accessing or deleting files, or stealing session cookies which an attacker could use to hijack a user’s session. Hence, this could have impact on Confidentiality, Integrity and Availability of the system.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 33.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-34687
-
cpe:2.3:a:sap:sap_basis:700
-
cpe:2.3:a:sap:sap_basis:701
-
cpe:2.3:a:sap:sap_basis:702
-
cpe:2.3:a:sap:sap_basis:731
-
cpe:2.3:a:sap:sap_basis:740
-
cpe:2.3:a:sap:sap_basis:750
-
cpe:2.3:a:sap:sap_basis:751
-
cpe:2.3:a:sap:sap_basis:752
-
cpe:2.3:a:sap:sap_basis:753
-
cpe:2.3:a:sap:sap_basis:754
-
cpe:2.3:a:sap:sap_basis:755
-
cpe:2.3:a:sap:sap_basis:756
-
cpe:2.3:a:sap:sap_basis:757
-
cpe:2.3:a:sap:sap_basis:758
-
cpe:2.3:a:sap:sap_basis:795
-
cpe:2.3:a:sap:sap_basis:796